Defending at Machine Speed
AI just rewrote the offense-defense balance in cybersecurity. Jim Sherlock, VP of AI & Cybersecurity R&D at ProCircular, joins Alan Shimel on Techstrong TV to explain why a penetration test report is stale within a week of delivery, why annual scans no longer protect anyone, and why the only realistic counter to offensive AI is defensive AI. Drawing on nearly 30 years across DISA, SIPRNet, Pearson’s cloud migration, and now ProCircular’s offensive and application security teams, Jim breaks down the new threat economics for small and mid-sized businesses: attackers chaining low- and medium-severity findings into critical breaches at machine speed, the case for risk-transfer to SaaS and the cloud, why every SMB still needs a vCISO, patch cadence, and a real incident-response plan, and the Log4j war story that proved why asset visibility is non-negotiable.
Transcript
Hey everyone, welcome back here to Techstrong TV. I want to introduce you to my next guest. His name is Jim Sherlock.
Jim is the VP for AI and Cybersecurity R&D at ProCircular. Hey, Jim. How are you?
I am great. Thanks for inviting me on to the show. Appreciate the- My pleasure ...
the opportunity here. Yeah. I- I appreciate you coming on.
Yeah. I- Tell us a little bit about, I gave your title, but beyond the title, Jim, give us your story. Yeah.
So I've been in technology for close to 30 years now. I started in the defense space, so I supported the Defense Information Systems Agency, doing work in a public- Sometimes referred to as DISA ... DISA, exactly.
Right. I did work on the SIPRNet and networking side, and ended up really cutting my teeth in tech, spending a couple decades at Pearson, where I helped Pearson, the largest assessment and testing vendor in the world, move from paper-based bubble form testing to online. So I have a strong background in infrastructure software, and then I was responsible for helping Pearson move from data centers into the cloud.
So I think a lot of the- Very cool ... a lot of the transitions and paradigm shifts that we're seeing in AI, I feel like I kind of went through those 15 to 20 years ago, in moving an organization into the cloud. And I've spent my last seven years or so both at Pearson and then now a couple of years at ProCircular in the security space.
I lead application security teams. I lead the offensive team at ProCircular and I'm using AI within our organization to help accelerate all of our teams, our defensive teams, our security operations center, our governance risk and compliance, all of that stuff. So I get to dabble in AI and help it accelerate our company.
And our mission here in the Midwest is, as a cybersecurity services vendor, we support small and medium-sized businesses in protecting their infrastructure, protecting their estate, helping them implement best practices, and everything under the sun as it pertains to cybersecurity. Absolutely. Back in the day before I started Techstrong, I did a couple of cybersecurity startups.
One of which, eventually, we came to the conclusion that security was just too hard for many SMBs, and they really needed the MSSP model was the way to go, right? And so we acquired an MSSP, built out, added our own IP into it. We actually were doing a lot of work for the federal government and DOD back then, too, so I know about SIPRNet and all of that good stuff.
But in any event, it really hasn't changed. It's probably gotten worse, I bet, right? Mm-hmm.
Security today is just not easy for... It's not easy for anyone, let alone if you're not a Fortune 100 kind of organization. Jim, if you don't mind, I know time is short today, we wanted to talk a little bit about Glasswing, Mythos, and what this means for the broader market, right?
Look, Mythos was announced now about, I guess, what, about two months ago? Mm-hmm. Maybe three, with Glasswing, and they started to expand beyond the initial, I think it was 40 companies or whatever that had been given access.
Then, of course, Anthropic released Fable, and shortly thereafter, this government clamped down on any foreign nationals using it and so forth, caused the whole thing to come to an end. But of course, the thing about this kind of stuff is it's like sand in your fist, Jim, right? The harder you squeeze, the more it comes out between your fingers.
I'm interested, from where you sit and your clients, what do you think about all this? I think the biggest change and the biggest shock to the system as it pertains to small and medium-sized businesses is going to be the pace at which vulnerabilities are discovered and exploit code is released. I think that that pace, when we're talking about models that are as good as some of the best bug bounty hunters, but at machine speed, I don't think that many small and medium-sized businesses are currently set up to deal with that kind of pace.
I think most are used to standard patch schedules, if they have them at all. Mm-hmm. They have cadences that are set.
They may get annual or semi-annual security testing or audits or attestations. But I think that the big shock that these models will bring to that market is that a week after you get that large-scale penetration test done and the report is delivered, those findings are stale. Because no longer is it what did we change that introduced risks in our environment?
The bigger risk is what is changing underfoot? So you may yourself lock your system down and not make changes as to remove risk, but the code that you're running, the open source projects from which all of your SaaS platforms are built, those are going to be constantly under attack, vulnerabilities found in them. And if you're not able to, as an organization, one, know what you're running, and then two, have a mechanism in place to effectively patch quickly, it's going to be too little too late.
Yeah. This is why I brought up the story about the MSSPs. I saw this in 2007- Mm-hmm ...
2008, I think. Well, 2007, certainly, maybe even 2006. This just is beyond anything like that we've seen.
If there's good news, here's the good news. I think a lot of small, medium businesses, and I think of TekStrong as a small, medium business. We're a small group here.
So much of our infrastructure is not our infrastructure, it's SaaS, right? Mm-hmm. And, we talk about AI causing a SaaS apocalypse perhaps because we could build these things ourselves.
But that's exactly why you use SaaS for, it's exactly why I go to the cloud. I'm counting on them having a bigger security budget and more security knowhow than me. I want my SaaS apps, though they may be open source under the hood.
Mm-hmm. I want them to be patching and making sure they're using the latest versions of open source and securing them because I know there's no way on this earth that I have that- Mm-hmm ... capability myself.
And so does this wind up causing SMBs to go more into SaaS to offload that responsibility? Yeah, I think that that's an inevitable conclusion. It's all about risk and risk transfer, and- Yeah ...
at the end of the day, I cannot build and manage a server any better than Amazon can. In fact, that is one of their primary, AWS's primary value propositions. So I defer to them, which is why a lot of those vendors were in that first wave of Glasswing.
They quite literally power the underpinning of everything else that's running on top of it. But yeah, I think it's enough for a small and medium-sized business just to have a virtual CISO, or even a patch cadence or security policies, to ask them to adopt a pattern of continuous patching and continuous application vulnerability scanning on their own, that is not their strength. They're not positioned for that.
And frankly, what we're really talking about is using these AI models in a defensive nature because our only chance to stay on top of this from a detection and remediation standpoint is to use those same tools that are being used to identify the vulnerabilities, but use them in a defensive manner. And that's really what I think small and medium-sized businesses will be missing if they do try to do it on their own. Yeah.
So I call this AI scale, right? Mm-hmm. It's the velocity, it's the scope, just the pure scope of it.
An SMB is not going to be able to keep up with that, I'm sorry. There's no way. And I think the other angle to this though, Jim, is we used to spend a lot of our time trying to find vulnerabilities.
Mm-hmm. And the fact of the matter, look, another security company I was involved in had a vulnerability management system. It was Nessus-based back in the day, early 2000s.
What we found is most organizations, and back then, like you mentioned, they were scanning once a year, maybe twice a year. Production. Half of them didn't even scan pre-deployment.
But the fact of the matter was, even back then, they couldn't keep up with the amount of vulnerabilities that were reported, and so they'd have to prioritize to get the most bang for the buck and try to fix the most important ones. Now, what are they supposed to do when they're buried, literally buried- Mm-hmm ... in these vulnerabilities, right?
So now I think the emphasis more than ever is on prioritization. How do I remediate if not flat-out patch- Yeah ... the most important things?
It's going to be really difficult too because the traditional start with criticals and highs and maybe some sunny day you'll get two mediums and lows, but probably never and they'll always be on your report. But what AI is doing in this accelerated velocity of discovery is not only finding critical and high vulnerabilities, which it is, but being able to chain together multiple lower-severity findings to produce a net effect of a significant and critical finding. So it isn't even going to be sufficient going forward to just start from the top and work your way down, because it's entirely possible that the attack vector that will be the source of your next breach will come from multiple lower-severity vulnerabilities that were exploited in combination with each other that then have the net effect of compromising your system or leaking data.
Agreed. Agreed, man. Jim, we're almost out of time.
I'm going to ask you, boil it down for us, for our customers out here. A lot of them are SMBs. Actually, I think something like 42% of our audience is under 100 employees.
Mm-hmm. Right? Because 52% is 1,000 and up.
It's crazy. We have this dumbbell thing going on. Either they're really big or they're small.
Mm-hmm. There's not a lot of in-between. But for everyone, this affects everyone.
What's the best thing to be doing right now? I think the most practical thing to be doing is dusting off your incident response plan, and giving it an extremely close look. Gather the stakeholders together, enlist the help of a professional who facilitates tabletop exercises, and practice.
I lived through the Log4j fiasco. Yeah. I think it was over the holidays.
Yeah. I learned very quickly that our team had no idea where we had Log4j within our 22,000 instances running in AWS. That was not a good time to- No, it wasn't fun.
No, it was not a good time. I think, know what you're running, get your incident response plan out, and make sure that everybody has eyeballs on it and that you rehearse it, because there will be incidents, and I think that the degree to which you're able to respond to them quickly and efficiently will probably have more to do with your overall success than any other variable that you can change right now. I love it.
Hey, man. Jim, I appreciate you coming on here. I know it's a bit of a crazy time in the security world.
Keep up the good work, and we'll talk to you soon. All right. Thank you very much.
Thanks for having me. All right. Jim Sherlock, VP for AI and Cybersecurity, R&D at ProCircular, here on Techstrong TV.
We're going to take a break. We'll be back in a moment.